Release of Asterinas kernel 0.18, written in Rust and compatible with Linux

The release of project Asterinas 0.18 has been announced, developing a kernel written in Rust intended for use in general-purpose operating systems. The kernel provides an ABI (Application Binary Interface) compatible with the Linux kernel and can be used as a substitute. Simultaneously, the Asterinas NixOS distribution is being developed, combining the Asterinas kernel with the NixOS system environment. The project code is distributed under the MPL (Mozilla Public License).

Currently, the kernel implements about 240 Linux system calls. In the Asterinas NixOS distribution, the functionality over the Asterinas kernel has been verified for over 100 packages from NixOS. Among the supported packages are: Xfce, Firefox, bash, systemd, Podman, QEMU, rsync, Apache httpd, nginx, SQLite, Redis, Clang, GCC, Go, Lua, Node.js, OpenJDK, Perl, PHP, Python, Ruby, Rust, Git, FFmpeg, PyTorch, TensorFlow, Ollama, and Codex.

The kernel offers full support for the x86-64 architecture, partial support for RISC-V 64, and x86-64 with Intel TDX-based isolation, as well as initial support for the LoongArch 64 architecture. The main target areas include systems tied to Linux ABI but requiring a higher level of security. For example, Asterinas is suggested for forming system environments that are protected, virtuele machines, for the isolation of which technologies such as ARM CCA, AMD SEV, and Intel TDX are used, as well as on the host system side that ensures the launch of containers.

To reduce the likelihood of memory-related errors, which are the main source of the most dangerous vulnerabilities, the Asterinas project employs the Rust programming language and a strategy of limited usage of unsafe blocks. The kernel is built using the framekernel architecture, which attempts to combine the isolation capabilities of microkernels with the efficiency of monolithic kernels.

De kerncomponenten in Asterinas zijn geplaatst in een gedeeld adresruimte, en de beveiliging wordt bereikt door logisch gescheiden beveiligde code en code die kwetsbaarheden kan bevatten. De kern is verdeeld in twee delen, geschreven in Rust: OS Framework en OS Services. In OS Services is het gebruik van unsafe-blokken verboden, en alle low-level operaties die code in unsafe-blokken vereisen, zijn overgebracht naar OS Framework en zijn alleen toegankelijk via een high-level API. Alle systeemaanroepen, bestandssystemen en stuurprogramma's worden op het niveau van OS Services geĆÆmplementeerd en kunnen geen unsafe-blokken bevatten.

Voor de ontwikkeling van systeemservices en kernmodules is de OSDK (Operating System Development Kit) beschikbaar, die de cargo-osdk-tool biedt voor het creƫren, bouwen, testen en uitvoeren van componenten van het besturingssysteem. Voor ontwikkelaars is een set bibliotheken, de OSTD (Operating System Standard Library), voorbereid, inclusief een bewerking van de standaard Rust-bibliotheken (crate std), aangepast voor gebruik in de componenten van het besturingssysteem.

Onder de wijzigingen in versie 0.18:

  • In het kader van de implementatie van Asterinas als gast-systeem in VM-containers zoals Kata Containers en Confidential Containers, is de ondersteuning voor IPC-namespaces en cgroup, nsfs (/proc/[pid]/ns), cgroups, virtio-fs (voor toegang tot een gedeeld bestandssysteem met het host-systeem), virtio-rng (/dev/hwrng voor entropie aan de pseudowillekeurige getallengenerator) en vsock (voor interactie tussen host- en gast-systemen) gerealiseerd.
  • De systeemaanroep ptrace en debug-mogelijkheden in de gebruikersruimte met GDB en strace zijn geĆÆmplementeerd.
  • Een nieuwe implementatie van het ext2-bestandssysteem is aangeboden en een NVMe-stuurprogramma is toegevoegd. In VFS is een Dentry-mechanisme (Directory Entry) toegevoegd en de implementatie van de pagina-cache is herzien.
  • In de Asterinas NixOS-distributie is de mogelijkheid toegevoegd om Codex, QEMU en Firefox te starten.
  • Systeemaanroepen pidfd_getfd, pidfd_send_signal, pivot_root zijn toegevoegd.
  • Een initiĆ«le implementatie is toegevoegd. ondersteuning voor IPv6.
  • Een capabilities-systeem is geĆÆmplementeerd voor het delegeren van afzonderlijke geprivilegieerde operaties.
  • Een initiĆ«le implementatie van het LSM-framework (Linux Security Modules) is toegevoegd.

Bron: opennet.ru

Koop betrouwbare webhosting met bescherming tegen DDoS, VPS VDS servers šŸ”„ Koop betrouwbare webhosting met bescherming tegen DDoS, VPS VDS servers | ProHoster